CVE-2026-108942 | philz1337x clarity-upscaler up to cfbdb842c6c839c8e97741722b8cf9a4b7662d98 Extra Networks Card Rendering ui_extra_networks.py create_html_for_item description cross site scripting (Issue 72)
A vulnerability classified as problematic was found in philz1337x clarity-upscaler up to cfbdb842c6c839c8e97741722b8cf9a4b7662d98. This impacts the function create_html_for_item of the file modules/ui_extra_networks.py of the component Extra Networks Card Rendering. The manipulation of the argument Description results in cross site scripting.
This vulnerability is identified as CVE-2026-108942. The attack can be executed remotely. There is not any exploit available.
This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable.
All versions in the repository are affected, as the codebase is based on AUTOMATIC1111/stable-diffusion-webui v1.7.0 code. Upstream AUTOMATIC1111/stable-diffusion-webui (v1.8.0, released March 1, 2024) contains the fix. The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More